What ASL-3 Actually Means: Anthropic’s Biorisk Threshold Explained

What ASL-3 Actually Means: Anthropic’s Biorisk Threshold Explained
What ASL-3 Actually Means: Anthropic’s Biorisk Threshold Explained
ASL-3
level at which Anthropic says models could provide serious uplift on bioweapons
4 labs
Anthropic, OpenAI, Google DeepMind, xAI with frontier safety eval commitments
VCT
Virology Capabilities Test, Anthropic’s red team benchmark for bioweapon uplift
2x
ASL-3 trigger: model doubles the number of people who could create mass-casualty bio threat

Anthropic’s Responsible Scaling Policy defines four AI Safety Levels, with ASL-3 being the threshold at which the company says its models could provide serious uplift to someone attempting to create biological, chemical, nuclear, or radiological weapons with the potential for mass casualties. The company’s stated commitment is to pause deployment and restrict access to models that reach ASL-3 until specified safety measures are in place. As of the Claude 3 and Claude 4 generations, Anthropic has assessed its models as ASL-2: more capable than a Google search for harmful information but not yet providing the kind of end-to-end synthesis-level uplift that would constitute ASL-3.

The Virology Capabilities Test

Anthropic uses the Virology Capabilities Test as part of its ASL evaluation process for biological risks. The VCT is a red-team benchmark assessing how much uplift an LLM provides to someone attempting tasks in the bioweapon creation pathway: pathogen identification, acquisition, enhancement of transmissibility or lethality, and weaponization. The specific questions, scoring methodology, and threshold score that would trigger ASL-3 designation are internal to Anthropic. External researchers cannot independently verify whether a model passes or fails the VCT.

What the Scale AI Study Found

The February 2025 study from Scale AI and SecureBio (arXiv 2602.23329) provided the most detailed public empirical data on LLM bioweapon uplift to date. The study recruited biology experts and novices, had them attempt tasks relevant to bioweapon creation with and without LLM assistance, and measured the gap. The headline finding: LLM assistance gave novices approximately 4x uplift on the biological tasks tested. Whether that 4x figure constitutes ASL-3-level uplift depends on interpretation of the threshold that Anthropic has not made fully public.

The Limitations of Self-Assessment

The RSP framework is self-regulatory. Anthropic evaluates its own models against its own thresholds using its own methodology and makes its own determination about whether to deploy. There is no independent third-party verification of the VCT results, no government audit of the threshold-setting methodology, and no legal consequence for deploying a model that fails internal safety evaluations. All major frontier lab safety frameworks are currently self-regulatory. The question is whether voluntary frameworks with self-assessment are adequate given the stakes, or whether bioweapon uplift risk requires the kind of independent verification that the Nuclear Regulatory Commission applies to nuclear facilities. The June 2026 export control directive against Fable 5 and Mythos 5 is the closest real-world test of that question so far, and it did not resolve it cleanly: the government intervened using export law rather than a biosecurity framework, over a cybersecurity finding rather than a bioweapons one, and largely without publishing the technical basis for its own determination either.

Related reading: LLMs Give Novice Biologists 4x Uplift on Dangerous Tasks | Protein Language Models and Biosecurity Dual-Use Risk | DNA Synthesis Screening Cannot Keep Up With AI-Designed Sequences | How an Export Law Built for Chips Took Down Fable 5

Primary sources: Anthropic Responsible Scaling Policy (September 2023, updated 2024); Mouton CA et al. (Scale AI/SecureBio), arXiv:2602.23329 (February 2025).

Discover more from My Written Word

Subscribe now to keep reading and get access to the full archive.

Continue reading